Symmetric and asymmetric encryption method with arbitrarily selectable one-time keys
Abstract
The present invention concerns symmetric and asymmetric encryption key management methods and sets of encryption methods to encrypt and decrypt arbitrary data, which can be divided into n (n>= 2 ) data blocks D 0 , . . . , D n−1 , continuous data streams of known or unknown length or sequences of a known or unknown number of messages between at least two communication partners using variable—in particular arbitrarily selectable and/or randomized one-time—encryption keys. The current invention overcomes prior art by encrypting arbitrary data, which can be divided into a given number of n data blocks, a continuous data stream of unknown length, a sequence of a known or unknown number of messages between at least two communication partners, using encryption methods to encrypt each individual data block with an arbitrarily selectable encryption algorithm and a new encryption key resulting from an arbitrarily selectable encryption key generator in dependence of a basic encryption key and arbitrarily—i.e. pseudo or absolutely randomly—selectable partial keys, where each encrypted data block ED i contains the original data D i and a new partial key PK i+1 for the next data block ED i+1 . By choice of particular encryption algorithms and encryption key generators perfect backward and forward security can be obtained, such that an attacker must know the complete encryption history to decrypt past and future encrypted data.
Claims
exact text as granted — not AI-modifiedI claim:
1 . Method to encrypt arbitrary data D, which data D can be divided into n (n>=2) data blocks D 0 , . . . , D n−1 , where each data block D i is of arbitrary size, whereby
i. the encryptor E knows at least one arbitrary secret basic encryption key BEK, which basic encryption key BEK is used in iteration i=0 as encryption key EK 0 =BEK, and ii. the decryptor D knows at least one arbitrary secret basic decryption key BDK corresponding to said basic encryption key BEK, which basic decryption key BDK is used in iteration i=0 as decryption key DK 0 =BDK, and iii. the encryptor E starting at i=0 iteratively for all integer i<n—to encrypt data block D i
first chooses an arbitrary partial key PK i+1 ,
second calculates the encrypted data block ED i using an arbitrary encryption algorithm EA i in dependence of EK 0 , . . . , EK i , D 0 , . . . , D i , and PK 1 , . . . , PK i+1 , i.e.
ED i =EA i (EK 0 , . . . ,EK i ,D 0 , . . . ,D i ,PK 1 , . . . ,PK i+1 ), and
third determines the encryption key EK i+1 using an arbitrary encryption key generator EKG i+1 in dependence of EK 0 , . . . , EK i , D 0 , . . . ,D i , and PK 1 , . . . ,PK i+1 , i.e.
EK i+1 =EKG i+1 ( EK 0 , . . . ,EK i ,D 0 , . . . ,D i ,PK 1 , . . . ,PK i+1 ), and
iv. the decryptor D starting at i=0—to decrypt data block ED 0 —determines the original data block D 0 and partial key PK 1 using a decryption algorithm DA 0 corresponding to said encryption algorithm EA 0 in dependence of said decryption key DK 0 and said encrypted data block ED 0 , i.e. ( D 0 ,PK 1 )= DA 0 ( DK 0 ,ED 0 ), and starting at i=1 iteratively for all integer i<n—to decrypt data block ED i —determines the original data block D i and partial key PK i+1 using a decryption algorithm DA i corresponding to said encryption algorithm EA i in dependence of DK 0 , . . . , DK i , D 0 , . . . , D i−1 , and PK 1 , . . . , PK i , i.e. ( D i ,PK i+1 )= DA i ( DK 0 , . . . ,DK i ,D 0 , . . . ,D i−1 ,ED i ,PK 1 , . . . ,PK i ), and for all i iteratively determines key DK i+1 using decryption key generator DKG i+1 corresponding to said encryption key generator EKG i+1 in dependence of DK 0 , . . . , DK i , D 0 , . . . , D i , and PK 1 , . . . , PK i+1 , i.e. DK i+1 =DKG i+1 ( DK 0 , . . . ,DK i ,D 0 , . . . ,D i ,PK 1 , . . . ,PK i+1 ).
2 . Method to encrypt a continuous data stream DS of unknown length, which data stream DS can be divided into a sequence of an unknown number of data blocks D i (i>0), where each data block D i is of arbitrary size, whereby
i. the encryptor E knows at least one arbitrary secret basic encryption key BEK, which basic encryption key BEK is used in iteration i=0 as encryption key EK 0 =BEK, and ii. the decryptor D knows at least one arbitrary secret basic decryption key BDK corresponding to said basic encryption key BEK, which basic decryption key BDK is used in iteration i=0 as decryption key DK 0 =BDK, and iii. the encryptor E starting at i=0 iteratively for all integer i—to encrypt data block D i
first chooses an arbitrary partial key PK i+1 ,
second calculates the encrypted data block ED i using an arbitrary encryption algorithm EA i in dependence of EK 0 , . . . , EK i , D 0 , . . . , D i , and PK 1 , . . . , PK i+1 , i.e.
ED i =EA i ( EK 0 , . . . ,EK i ,D 0 , . . . ,D i ,PK 1 , . . . ,PK i+1 ), and
third determines the encryption key EK i+1 using an arbitrary encryption key generator EKG i+1 in dependence of EK 0 , . . . , EK i , D 0 , . . . , D i , and PK 1 , . . . , PK i+1 , i.e.
EK i+1 =EKG i+1 ( EK 0 , . . . ,EK i ,D 0 , . . . ,D i ,PK 1 , . . . ,PK i+1 ), and
iv. the decryptor D starting at i=0—to decrypt data block ED 0 —determines the original data block D 0 and partial key PK 1 using a decryption algorithm DA 0 corresponding to said encryption algorithm EA 0 in dependence of said decryption key DK 0 and said encrypted data block ED 0 , i.e. ( D 0 ,PK 1 )= DA 0 ( DK 0 ,ED 0 ), and starting at i=1 iteratively for all integer i—to decrypt data block ED i —determines the original data block D i and partial key PK i+1 using a decryption algorithm DA i corresponding to said encryption algorithm EA i in dependence of DK 0 , . . . , DK i , D 0 , . . . , D i−1 , and PK 1 , . . . , PK i , i.e. ( D i ,PK i+1 )= DA i ( DK 0 , . . . ,DK i ,D 0 , . . . ,D i−1 ,ED i ,PK 1 , . . . ,PK i ), and for all i iteratively determines decryption key DK i+1 using decryption key generator DKG i+1 corresponding to said encryption key generator EKG i+1 in dependence of DK 0 , . . . , DK i , D 0 , . . . , D i , and PK 1 , . . . , PK i+1 , i.e. DK i+1 =DKG i+1 ( DK 0 , . . . ,DK i ,D 0 , . . . ,D i ,PK 1 , . . . ,PK i+1 ).
3 . Method to encrypt a sequence of n messages M i (0<=i<n), where each message M i is of arbitrary size, between an arbitrary number p>=2 of communication partners P 1 , . . . , P p , whereby
i. each encryptor of the communication partners P 1 , . . . , P p knows at least one arbitrary secret basic encryption key BEK, which basic encryption key BEK is used in iteration i=0 as encryption key EK 0 =BEK, and ii. each decryptor of the communication partners P 1 , . . . , P p knows at least one arbitrary secret basic decryption key BDK corresponding to said basic encryption key BEK, which basic decryption key BDK is used in iteration i=0 as decryption key DK 0 =BDK, and iii. starting at i=0 iteratively for all integer i with i<n exactly one communication partner P ji (1<= ji <=p)—to encrypt data block D i
first chooses an arbitrary partial key PK i+1 ,
second calculates the encrypted message EM i using an arbitrary encryption algorithm EA i in dependence of EK 0 , . . . , EK i , M 0 , . . . , M i , and PK 1 , . . . , PK i+1 , i.e.
EM i =EA i ( EK 0 , . . . ,EK i ,M 0 , . . . ,M i ,PK 1 , . . . ,PK i+1 ), and
third determines the encryption key EK i+1 using an arbitrary encryption key generator EKG i+1 in dependence of EK 0 , . . . , EK i , M 0 , . . . , M i , and PK 1 , . . . , PK i+1 , i.e.
EK i+1 =EKG i+1 ( EK 0 , . . . ,EK i ,M 0 , . . . ,M i ,PK 1 , . . . ,PK i+1 ), and
fourth transmits the encrypted message EM i to all communication partners P 1 , . . . , P p except P ji , and
iv. starting at i=0 iteratively for all integer i all communication partners P 1 , . . . , P p except P ji receive the encrypted message EM i from P ji , and
to decrypt data block EM 0 —determine the original message M 0 and partial key PK 1 using a decryption algorithm DA 0 corresponding to said encryption algorithm EA 0 in dependence of said decryption key DK 0 and said encrypted message EM 0 , i.e.
( M 0 ,PK 1 )= DA 0 ( DK 0 ,EM 0 ), and
to decrypt message EM i (i>0)—determine the original message M i and partial key PK i+1 using a decryption algorithm DA i corresponding to said encryption algorithm EA i in dependence of DK 0 , . . . , DK i , D 0 , . . . , D i−1 , and PK 1 , . . . , PK i , i.e.
( M i ,PK i+1 )= DA i ( DK 0 , . . . ,DK i ,M 0 , . . . ,M i−1 ,EM i ,PK 1 , . . . ,PK i ), and
for all i iteratively determine decryption key DK i+1 using decryption key generator DKG i+1 corresponding to said encryption key generator EKG i+1 in dependence of DK 0 , . . . , DK i , M 0 , . . . , M i , and PK 1 , . . . , PK i+1 , i.e.
DK i+1 =DKG i+1 ( DK 0 , . . . ,DK i ,M 0 , . . . . ,M 1 ,PK 1 , . . . ,PK i+1 ).
4 . Method to encrypt a sequence of an unknown number of messages M i (0<=i), where each message M i is of arbitrary size, between an arbitrary number p>=2 of communication partners P 1 , . . . , P p , whereby
i. each encryptor of the communication partners P 1 , . . . , P p knows at least one arbitrary secret basic encryption key BEK, which basic encryption key BEK is used in iteration i=0 as encryption key EK 0 =BEK, and ii. each decryptor of the communication partners P 1 , . . . , P p knows at least one arbitrary secret basic decryption key BDK corresponding to said basic encryption key BEK, which basic decryption key BDK is used in iteration i=0 as decryption key DK 0 =BDK, and iii. starting at i=0 iteratively for all integer i exactly one communication partner P ji (1<=ji<=p)—to encrypt data block D i
first chooses an arbitrary partial key PK i+1 ,
second calculates the encrypted message EM i using an arbitrary encryption algorithm EA i in dependence of EK 0 , . . . , EK i , M 0 , . . . , M i , and PK 1 , . . . , PK i+1 , i.e.
EM i =EA i ( EK 0 , . . . ,EK i ,M 0 , . . . ,M i ,PK 1 , . . . ,PK i+1 ), and
third determines encryption key EK i+1 using an arbitrary encryption key generator EKG i+1 in dependence of EK 0 , . . . , EK i , M 0 , . . . , M i , and PK 1 , . . . , PK i+1 , i.e.
EK i+1 =EKG i+1 ( EK 0 , . . . ,EK i ,M 0 , . . . ,M i ,PK 1 , . . . ,PK i+1 ), and
fourth transmits the encrypted message EM i to all communication partners P 1 , . . . , P p except P ji , and
iv. starting at i=0 iteratively for all integer i all communication partners P 1 , . . . , P p except P ji receive the encrypted message EM i from P ji , and
to decrypt data block EM 0 —determine the original message M 0 and partial key PK 1 using a decryption algorithm DA 0 corresponding to said encryption algorithm EA 0 in dependence of said decryption key DK 0 and said encrypted message EM 0 , i.e.
( M 0 ,PK 1 )= DA 0 ( DK 0 ,EM 0 ), and
to decrypt message EM i (i>0)—determine the original message M i and partial key PK i+1 using a decryption algorithm DA i corresponding to said encryption algorithm EA i in dependence of DK 0 , . . . , DK i , D 0 , . . . , D i−1 , and PK 1 , . . . , PK i , i.e.
( M i ,PK i+1 )=DA i (DK 0 , . . . ,DK i ,M 0 , . . . ,M i−1 ,EM i ,PK 1 , . . . ,PK i ), and
for all i iteratively determine decryption key DK i+1 using decryption key generator DKG i+1 corresponding to said encryption key generator EKG i+1 in dependence of DK 0 , . . . , DK i , M 0 , . . . , M i , and PK 1 , . . . , PK i+1 , i.e.
DK i+1 =DKG i+1 ( DK 0 , . . . ,DK i ,M 0 , . . . ,M i ,PK 1 , . . . ,PK i+1 ).
5 . Encryption method according to one of the claims 1 or 3 , whereby—during the last iteration i=n−1—the encryptor does not determine encyption key EK n and/or at least one decryptor does not determine decyption key DK n .
6 . Encryption method according to one of the previous claims, whereby at least one basic encryption key BEK or at least basic decryption key BDK is initially exchanged between the encryptor and the decryptor(s) resp. message recipient(s) using a state of the art key exchange method.
7 . Encryption method according to one of the previous claims, whereby the encryption only starts if at least one encryptor has proven the knowledge of the at least one basic encryption key BEK using a state of the art knowledge proof method.
8 . Encryption method according to claim 7 , whereby the knowledge proof does not require the explicit transmission of the basic encryption key BEK between the communication partners.
9 . Encryption method according to one of the previous claims, whereby the encryption only starts if at least one decryptor has proven the knowledge of the at least one basic decryption key BDK corresponding to said basic encryption key BEK using a state of the art knowledge proof method.
10 . Encryption method according to claim 9 , whereby the knowledge proof does not require the explicit transmission of the basic decryption key BDK between the communication partners.
11 . Encryption method according to one of the previous claims, whereby at least one of the partial keys PK i (i>0) is chosen by a pseudo random number generator.
12 . Encryption method according to one of the previous claims, whereby at least one of the partial keys PK i (i>0) is chosen by an absolute random number generator.
13 . Encryption method according to one of the previous claims, whereby the basic encryption key BEK is identical to the basic decryption key BDK.
14 . Encryption method according to one of the previous claims, whereby in at least one iteration i the encryption key generator EKG i is identical to the decryption key generator DGK i .
15 . Encryption method according to one of the previous claims, whereby the same encryption and decryption algorithms are used in at least two iterations.
16 . Encryption method according to one of the previous claims, whereby for at least one i>=0 the encryptor resp. the sending communication partner chooses the encryption algorithm EA i out of a given set SEA i of different encryption algorithms in dependence of the already transmitted and therefore known encryption keys EK 0 , . . . , EK i , data D 0 , . . . , D i−1 , partial keys PK 1 , . . . , PK i or the encrypted data ED i resp. the encrypted message EM i , and the decryptor resp. receiving communication partner is able to determine decryption algorithm DA i corresponding to said encryption algorithm EA i implicitly in dependence of the decryption keys DK 0 , . . . , DK i , data or messages D 0 /M 0 , . . . , D i−1 /M i−1 , partial keys PK 1 , . . . , PK i or the encrypted data ED i resp. message EM i out of a set of decryption algorithms SDA i corresponding to said set SEA i of encryption algorithms.
17 . Encryption method according to claim 16 , whereby in at least two iterations—i1 and i2—the set of encryption algorithms SEA i1 is identical to the set of encryption algorithms SEA i2 .
18 . Encryption method according to one of the previous claims, whereby for at least one i>0 encryption key EK i can be determined using an arbitrary encryption key generator EKG i in dependence of encryption keys EK 0 and EK i−1 as well as in dependence of partial key PK i , i.e. EK i =EKG i (EK 0 , EK i−1 , PK i ).
19 . Encryption method according to claim 18 , whereby in at least two iterations i and j the same encryption key generator EKG i =EKG j is used.
20 . Encryption method according to one of the previous claims, whereby for at least one i>=0 the encryptor resp. the sending communication partner chooses the encryption key generator EKG i+1 out of a given set SEKG i of different encryption key generators in dependence of encryption keys EK 0 , . . . , EK i , data or messages D 0 /M 0 , . . . , D i /M i , partial keys PK 1 , . . . , PK i+1 or the encrypted data ED i resp. the encrypted message EM i , and the decryptor resp. receiver is able to determine the decryption key generator DKG i corresponding to said encryption key generator EKG i+1 implicitly in dependence of decryption keys DK 0 , . . . , DK i , data or messages D 0 /M 0 , . . . , D i /M i , partial keys PK 1 , . . . , PK i+1 or encrypted data ED i resp. message EM i out of set SDKG i of decryption key generators corresponding to said set SEKG i of encryption key generators.
21 . Encryption method according to one of the previous claims, whereby for at least one i>0 original data D i resp. message M i is extended before encryption by arbitrarily selectable data ZD and said data ZD is removed after decryption.
22 . Encryption method according to claim 21 , whereby said additional data ZD is generated by a pseudo random number generator.
23 . Encryption method according to claim 21 , whereby said additional data ZD is generated by an absolute random number generator.Join the waitlist — get patent alerts
Track US2002191796A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.